EDBT 2026 Demo / reviewers in the wild / expert
Bogdan Ghita 0003
dblp:63/675 · also Bogdan V. Ghita, Bogdan Vladimir Ghita
· DBLP profile ↗
23ranked-venue papers
0as first author
5since 2021 · last 2026
0000-0002-1788-547XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 6Security and privacy · 6 · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 since 2021Software engineering, systems software and programming languages · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Virtual Lab for Learning AI Security and Adversarial Prompt Engineering
Dhanraj Jagadish Devadiga, Ievgeniia Kuzminykh, Hannah Cao, Bogdan Ghita 0003 |
ITiCSE (1) | 4 |
| 2024 | Network Slice Placement in Wireless Mesh NetworksabstractNetwork slicing is a key technology for 5G and future mobile networks. It enables the creation of different virtual networks on the same physical infrastructure. By applying network slicing to wireless mesh networks(WMNs), it’s possible to provide communication infrastructure in a quick and less complicated way. This paper shows an approach based on an evolutionary algorithm connecting multiple WMN nodes to a slice. The first step is modeling the WMN as an undirected graph to get a data structure for the algorithm. The paper then shows the procedure of the different steps of the algorithm. It also shows at which number of nodes to connect the algorithm outperforms a brute force approach. The final results shown in this paper are how the time complexity increases when adding additional nodes to the slices and increasing the network size. Alexander Seng, Ulrich Trick, Armin Lehmann, Bogdan Ghita 0003 |
IWCMC | 4 |
| 2023 | Brainwave-based authentication using features fusionabstractThis article investigates the use of human brainwaves for user authentication. We used data collected from 50 volunteers and leveraged the Support Vector Machine (SVM) as a classification algorithm for the case study. User recognition patterns are taken from a combination of blinking, attention concentration, and picture recognition emotion sequences. These actions impact alpha, beta, gamma, and theta brain waves, which are measured using several electrodes. Ten different electrode placement patterns are explored, with varied positioning on the head. For each placement position, four features are examined, for a total of 40 extracts in the learning model. Features are: 1) spectral information, 2) coherence, 3) mutual correlation coefficient, and 4) mutual information. Each feature type is trained by the SVM algorithm, and the 40 weak classifier candidates. Adaptive Boosting (AdaBoost), a type of machine learning, is then used to generate a robust classifier, which is subsequently used to create a model, and select features, used to accurately identify individuals for authentication purposes. Upon verifying the proposed method using 32 legitimate users and 18 intruders, we obtained an authentication error rate (ERR) of 0.52%, and a classification rate of 99.06%. Mahyar Taj Dini, Volodymyr Sokolov, Ievgeniia Kuzminykh, Bogdan Ghita 0003 |
Comput. Secur. | 4 |
| 2021 | Improved HTM Spatial Pooler with Homeostatic Plasticity ControlabstractHierarchical Temporal Memory (HTM)-Spatial Pooler (SP) is a Learning Algorithm for learning of spatial patterns inspired by the neo-cortex. It is designed to learn the pattern in a few iteration steps and to generate the Sparse Distributed Representation (SDR) of the input. It encodes spatially similar inputs into the same or similar SDRs memorized as a population of active neurons organized in groups called micro-columns. Findings in this research show that produced SDRs can be forgotten during the training progress, which causes the SP to learn the same pattern again and converts into the new SDR. This work shows that instable learning behaviour of the SP is caused by the internal boosting algorithm inspired by the homeostatic plasticity mechanism. Previous findings in neurosciences show that this mechanism is only active during the development of new-born mammals and later deactivated or shifted from cortical layer L4, where the SP is supposed to be active. The same mechanism was used in this work. The SP algorithm was extended with the new homeostatic plasticity component that controls the boosting and deactivates it after entering the stable state. Results show that learned SDRs remain stable during the lifetime of the Spatial Pooler. Damir Dobric, Andreas Pech, Bogdan Ghita 0003, Thomas Wennekers |
ICPRAM | 3 |
| 2021 | Anomaly Detection in Encrypted Internet Traffic Using Hybrid Deep LearningabstractAn increasing number of Internet application services are relying on encrypted traffic to offer adequate consumer privacy. Anomaly detection in encrypted traffic to circumvent and mitigate cyber security threats is, however, an open and ongoing research challenge due to the limitation of existing traffic classification techniques. Deep learning is emerging as a promising paradigm, allowing reduction in manual determination of feature set to increase classification accuracy. The present work develops a deep learning-based model for detection of anomalies in encrypted network traffic. Three different publicly available datasets including the NSL-KDD, UNSW-NB15, and CIC-IDS-2017 are used to comprehensively analyze encrypted attacks targeting popular protocols. Instead of relying on a single deep learning model, multiple schemes using convolutional (CNN), long short-term memory (LSTM), and recurrent neural networks (RNNs) are investigated. Our results report a hybrid combination of convolutional (CNN) and gated recurrent unit (GRU) models as outperforming others. The hybrid approach benefits from the low-latency feature derivation of the CNN, and an overall improved training dataset fitting. Additionally, the highly effective generalization offered by GRU results in optimal time-domain-related feature extraction, resulting in the CNN and GRU hybrid scheme presenting the best model. Taimur Bakhshi, Bogdan Ghita 0003 |
Secur. Commun. Networks | 2 |
| 2020 | Synergy of Trust, Blockchain and Smart Contracts for Optimization of Decentralized IoT Service Platforms
Besfort Shala, Ulrich Trick, Armin Lehmann, Bogdan Ghita 0003, Stavros Shiaeles |
AINA | 4 |
| 2020 | Detection of Insider Threats using Artificial Intelligence and VisualisationabstractInsider threats are one of the most damaging risk factors for the IT systems and infrastructure of a company or an organization; identification of insider threats has prompted the interest of the world academic research community, with several solutions having been proposed to alleviate their potential impact. For the implementation of the experimental stage described in this study, the Convolutional Neural Network (from now on CNN) algorithm was used and implemented via the Google Tensorflow program, which was trained to identify potential threats from images produced by the available dataset. From the examination of the images that were produced and with the help of Machine Learning, the question whether the activity of each user is classified as “malicious” or not for the Information System was answered. Vasileios Koutsouvelis, Stavros Shiaeles, Bogdan Ghita 0003, Gueltoum Bendiab |
NetSoft | 3 |
| 2020 | Digital forensics cloud log unification: Implementing CADF in Apache CloudStack
Nikolaos Dalezios, Stavros Shiaeles, Nicholas Kolokotronis, Bogdan Ghita 0003 |
J. Inf. Secur. Appl. | 4 |
| 2019 | Bandwidth Prediction Schemes for Defining Bitrate Levels in SDN-enabled Adaptive StreamingabstractThe majority of Internet video traffic today is delivered via HTTP Adaptive Streaming (HAS). Recent studies concluded that pure client-driven HAS adaptation is likely to be sub-optimal, given clients adjust quality based on local feedback. In [1], we introduced a network-assisted streaming architecture (BBGDASH) that provides bounded bitrate guidance for a video client while preserving quality control and adaptation at the client. Although BBGDASH is an efficient approach for video delivery, deploying it in a wireless network environment could result in sub-optimal decisions due to the high fluctuations. To this end, we propose in this paper an intelligent streaming architecture (denoted BBGDASH+), which leverages the power of time series forecasting to allow for an accurate and scalable networkbased guidance. Further, we conduct an initial investigation of parameter settings for the forecasting algorithms in a wireless testbed. Overall, the experimental results indicate the potential of the proposed approach to improve video delivery in wireless network conditions. Ali Edan Al-Issa, Abdelhak Bentaleb, Alcardo Alex Barakabitze, Thomas Zinner, Bogdan Ghita 0003 |
CNSM | 5 |
| 2019 | A Novel Features Set for Internet Traffic Classification using BurstinessabstractTraffic classification is an essential tool for network management and security. Traditional techniques such as port-based and payload analysis are ineffective as major Internet applications use dynamic port numbers and encryption. Recent studies have used statistical properties of flows to classify traffic with high accuracy, minimising the overhead limitations associated with other schemes such as deep packet inspection (DPI). Classification accuracy of statistical flow-based approaches, however, depends on the discrimination ability of the traffic features used. To this effect, the present paper customised the popular tcptrace utility to generate classification features based on traffic burstiness and periods of inactivity (idle time) for everyday Internet usage. An attempt was made to train. C5.0 decision tree classifier using the proposed features for eleven different Internet applications, generated by ten users. Overall, the newly proposed features reported. significant level of accuracy (-98%) in classifying the respective applications. Hussein Oudah, Bogdan Ghita 0003, Taimur Bakhshi |
ICISSP | 2 |
| 2019 | A novel approach for performance-based clustering and anagement of network traffic flowsabstractManagement of network performance comprises numerous functions such as measuring, modelling, planning and optimising networks to ensure that they transmit traffic with the speed, capacity and reliability expected by the applications, each with different requirements for bandwidth and delay. Overall, the objective of this paper is to propose a novel mechanism to optimise the network resource allocation through supporting the routing of individual flows, by clustering them based on performance and integrating the respective clusters with an SDN scheme. In this paper we have employed a particular set of traffic features then applied data reduction and unsupervised machine learning techniques, to derive an Internet traffic performance-based clustering model. Finally, the resulting data clusters are integrated within a unified SDN architectural solution, which improves network management by finding nearly optimal flow routing, to be evaluated against a number of traffic data sources. Muna Al-Saadi, Bogdan Ghita 0003, Stavros Shiaeles, Panagiotis G. Sarigiannidis |
IWCMC | 2 |
| 2019 | Enhancing Data Security in Cloud using Random Pattern Fragmentation and a Distributed NoSQL DatabaseabstractThe cloud computing model has become very popular among users, as it has proven to be a cost-effective solution to store and process data, thanks to recent advancements in virtualization and distributed computing. Nevertheless, in the cloud environment, the user entrusts the safekeeping of its data entirely to the provider, which introduces the problem of how secure such data is and whether its integrity has been maintained. This paper proposes an approach to the data security in cloud by utilizing a random pattern fragmentation algorithm and combining it with a distributed NoSQL database. This not only increases the security of the data by storing it in different nodes and scramble all the bytes, but also allows the user to implement an alternative method of securing data. The performance of the approach is compared to other approaches, along with AES 256 encryption. Results indicate a significant performance improvement over encryption, highlighting the capabilities of this method for cloud stored data, as it creates a layer of protection without additional overhead. Nelson L. Santos, Bogdan Ghita 0003, Giovanni Luca Masala |
SMC | 2 |
| 2019 | FCMDT: A novel fuzzy cognitive maps dynamic trust model for cloud federated identity management
Gueltoum Bendiab, Stavros Shiaeles, Samia Boucherkha, Bogdan Ghita 0003 |
Comput. Secur. | 4 |
| 2018 | Dynamic Neighbour Aware Power-controlled MAC for Multi-hop Ad-hoc networksabstractIn Ad-hoc networks, resources in terms of bandwidth and battery life are limited; so using a fixed high transmission power limits the durability of a battery life and causes unnecessary high interference while communicating with closer nodes leading to lower overall network throughput. Thus, this paper proposes a new cross layer MAC called Dynamic Neighbour Aware Power-controlled MAC (Dynamic NA-PMAC) for multi-hop Ad-hoc networks that adjust the transmission power by estimating the communication distance based on the overheard signal strength. By dynamically controlling the transmission power based on the receivable signal strength, the probability of concurrent transmission, durability of battery life and bandwidth utilization increases. Moreover, in presence of multiple overlapping signals with different strengths, an optimal transmission power is estimated dynamically to maintain fairness and avoid hidden node issues at the same time. In a given area, since power is controlled, the chances of overlapping the sensing ranges of sources and next hop relay nodes or destination node decreases, so it enhances the probability of concurrent transmission and hence an increased overall throughput. In addition, this paper uses a variable backoff algorithm based on the number of active neighbours, which saves energy and increases throughput when the density of active neighbours is less. The designed mechanism is tested with various random network scenarios using different traffic including CBR, Exponential and TCP in both scenarios (stationary and mobile with high speed) for single as well as multi-hop. Moreover, the proposed model is benchmarked against two variants of power-controlled mechanisms namely Min NA-PMAC and MaxRC-MinDA NA-PMAC to prove that using a fixed minimum transmission power may lead to unfair channel access and using different transmission power for RTS/CTS and Data/ACK leads to lower probability of concurrent transmission respectively. Jims Marchang, Roderick Douglas, Bogdan Ghita 0003, David Lancaster, Benjamin Sanders |
Ad Hoc Networks | 3 |
| 2017 | QoE-driven video enhancements in wireless networks through predictive packet dropsabstractIn recent years, video streaming traffic has increased exponentially over the Internet. This can be observed through the emergence of various video on demand sites such as Netflix, Amazon movies and others. In parallel, IEEE 802.11 (WiFi) technology has been deployed extensively from home to public areas. Although significant research has been done to address issues on video streaming through WiFi networks, it remains a challenging area. There are still interesting areas to be addressed especially to enhance user satisfaction in terms of Quality of Experience (QoE). After reviewing the existing research in improving video QoE through queuing in wireless environments, this paper propose a predictive packet drop technique to maintain a certain level of QoE based on predictive PSNR value without users' feedback. The proposed mechanism identifies packets as part of video frames and predicts the impact of their delay and loss on the resulting video performance. This reduces the need for client feedback and optimizes the resulting QoE of the delivered video. Therefore based on this information, the proposed algorithm can prioritize the video frames (I-,Por B-Frames) whether to queue or drop in scenarios where bandwidth and limited. This method is evaluated using NS-3 simulator with Evalvid module. Najwan Khambari, Bogdan Ghita 0003, Lingfen Sun |
WiMob | 2 |
| 2017 | Location based transmission using a neighbour aware with optimized EIFS MAC for ad hoc networksabstractIn a typical Ad Hoc network, participating nodes have scarce shared bandwidth and limited battery life resources, so resource optimization and enhancing the overall network performance are the primary aims to maintain functionality. This paper proposes a new cross layer Medium Access Control (MAC) algorithm called Location Based Transmission using a Neighbour Aware with optimized Extended Inter-Frame Spacing (EIFS) for Ad Hoc Networks MAC (LBT-NA with optimized-EIFS MAC) that aims to reduce the transmission power when communicating with the next hop receiver based on node's location which is made available during node deployment. However, node mobility is not taken into account in the study of this paper. According to the algorithm the node dynamically adjusts its transmission power, if there is an active neighbour located beyond the communicating source and destination pair to avoid hidden nodes. The new protocol also defines an optimized EIFS when frame collision, frame error or frame capture takes place, in-order to maintain a fair channel access among the contending nodes. The proposed MAC also uses a modified range of random backoff values, based on the degree of contention unlike IEEE 802.11 series which uses a fixed random backoff value for fresh frames irrespective of the degree of contention. Simulation results indicate that in a random topology with a random source and destination, when the two sources are separated by a minimum distance of 200 m, the performance gain of power controlled MAC over IEEE 802.11b ranges from 30% to 70% depending on the type of traffics in the network and the degree of fairness ranges from 62% to 99.99% for a location based MAC with minimum power transmission, whereas LBT-NA with optimized-EIFS MAC secures fairness index ranging from 75% to 99.99%. Communication with a node that is 20 m away can save 40% of the battery life in comparison to the traditional transmission power MAC from 802.11b. The validation tests demonstrate that the proposed algorithm increases battery life and reduces the interference impact on shorter distance communication and increases the probability of parallel transmission. The proposed protocol also provides a scope for active nodes to transmit with a higher degree of probability, providing higher degree of overall network throughput in the environment and alleviate the starvation of hidden node by using Dynamic EIFS scheme. Jims Marchang, Bogdan Ghita 0003, David Lancaster |
Ad Hoc Networks | 2 |
| 2016 | IP prefix hijack detection using BGP connectivity monitoringabstractIn spite of significant on-going research, the Border gateway protocol (BGP) still encompasses conceptual vulnerability issues regarding impersonating the ownership of IP prefixes for ASes (Autonomous Systems). In this context, a number of research studies focused on securing BGP through historical-based and statistical-based behavioural models. This paper suggests a novel method based on tracking the connectivity of suspicious ASes, which are received from a program tracing IP prefix hijacking signature. The paper uses Full Cross-Validation test to investigate the accuracy of the invented method and studies the similarity and differences between malicious and benign observations before they are classified. Classification might not be the appropriate technique to deal with IP prefix hijack detection on its own; therefore we propose to combine the two methods (signature and classification-based) in order to cover the limitations of both techniques. From a processing perspective, the outputs from signature-based method are used as inputs for the classification-based. The main features are extracted from the ASpath attributes of potentially suspicious ASes. The features are considered a mixture of the behavioural characteristics of connectivity among routers. The best five supervised classifiers were used in the previous researches and go with the characteristics of dataset will be used in this paper to evaluate the detection method. Under different learning algorithms, Random Forest and J48 classifiers, the detection method is able to detect the hijacks with 81% accuracy. Hussain Alshamrani, Bogdan Ghita 0003 |
HPSR | 2 |
| 2016 | User-Centric Network Provisioning in Software Defined Data Center EnvironmentabstractPresent data center (DC) network provisioning schemes primarily utilize conventional load-balancing technologies, offering individual application performance improvement. Diversity in application usage however, makes isolated application prioritization a performance caveat for users with varying application trends. The present paper proposes a user profiling approach to capture application trends based on generic flow measurements (NetFlow) and employs the extracted profiles to create DC traffic forwarding policies. The scheme allows operators to define a global profile and application hierarchy based on extracted profiles to prioritize traffic for individual user classes. The proposed design was tested by extracting user profiles from a realistic enterprise network, and further simulated to dynamically manage DC traffic using the software defined networking paradigm. Compared to conventional traffic management schemes, the frame delivery ratio and effective throughput of our design was significantly higher for high priority north-south user traffic as well as the inter-server east-west application traffic. Taimur Bakhshi, Bogdan Ghita 0003 |
LCN | 2 |
| 2016 | A Pre-clustering Method To Improve Anomaly DetectionabstractWhile Anomaly Detection is commonly accepted as an appropriate technique to uncover yet unknown network
misuse patterns and malware, detection rates are often diminished by, e.g., unpredictable user behavior,
new applications and concept changes. In this paper, we propose and evaluate the benefits of using clustering
methods for data preprocessing in Anomaly Detection in order to improve detection rates even in the presence
of such events. We study our pre-clustering approach for different features such as IP addresses, traffic characteristics
and application layer protocols. Our results obtained by analyzing detection rates for real network
traffic with actual intrusions indicates that our approach does indeed significantly improve detection rates and,
moreover, is practically feasible. Denis Hock, Martin Kappes, Bogdan Ghita 0003 |
SECRYPT | 3 |
| 2016 | OpenFlow-enabled user traffic profiling in campus software defined networksabstractThe recently emerging paradigm of software defined networking (SDN) predominantly employs the control-data plane OpenFlow protocol, offering centralized real-time programmability and monitoring of network devices. Effective SDN based traffic engineering using OpenFlow, particularly in campus networking however, requires sophisticated real-time user traffic visualization solution having minimum management overhead. To address the intuitive monitoring gaps in existing campus based SDN, the present paper proposes profiling campus user traffic to visualize real-time network workload and accurately provision resources. The design solely utilizes existing OpenFlow traffic measurements, subjected to k-means clustering to segregate users into different traffic classes (profiles) based on their application trends. To validate design feasibility, the present study derived six unique user traffic profiles from OpenFlow generated traffic statistics of a realistic campus switch over a two-week time frame. The derived profiles represented significant discrimination among user application trends and were further benchmarked for high stability (96.1-99.1%), to ascertain their viability for monitoring purposes. Additional simulation tests at varying user loads attributed minimum computational cost and low OpenFlow control overhead (4.02-4.96%) to the proposed approach, offering high scalability for real-time network monitoring and resource provisioning. Taimur Bakhshi, Bogdan Ghita 0003 |
WiMob | 2 |
| 2013 | Generic Real-Time Traffic Distribution Framework: Black RiderabstractIn order to manage the exponential growth of traffic in mobile network environments and the increasing requirements on bandwidth, Quality of Service (QoS) and mobility, the Mobile Network Operators (MNOs) infrastructure has to provide for an appropriate traffic distribution among the available networks. This paper proposes a new real-time traffic distribution framework, called Black Rider, which is context- and policy-based and supports heterogeneous wireless networks. It provides an architectural overview and a functional description of the framework and gives details of the three main functions - the context gathering, the coordination of external modules, and the distribution of the final commands or information to the end user device - to enable a real-time traffic management. Furthermore, a formal evaluation of the Black Rider against defined requirements for vertical handover and traffic offload is provided. Sandra Frei, Woldemar F. Fuhrmann, Bogdan Ghita 0003 |
ICCCN | 3 |
| 2011 | User-centric quality of service provisioningabstractCurrent Internet traffic includes a combination of peer to peer, web, and real time traffic which leads to unfair treatment for users or, when policed, an uneven distribution of resources to applications. This paper presents a novel extension to the Assured Forwarding per-hop-behaviour for a Diffserv-based network, enabling a more user-centric approach when provisioning for Quality of Service over IP networks. The proposed architecture, Congestion Aware Packet Scheduler (CAPS), is based on monitoring application-level performance metrics and adjusting resource allocation in order to optimise the end user resulting application performance while dynamically adapting to variable traffic conditions . The CAPS algorithm is validated through extensive simulations of a large Internet topology coupled with realistic traffic models. The results show that, irrespective of the combination of user traffic, the CAPS algorithm successfully manages the allocation of bandwidth across applications to provide the optimal aggregate-QoS, offering an improvement over alternative network configurations. Mark E. Culverhouse, Bogdan Ghita 0003, Paul L. Reynolds |
LCN | 2 |
| 2007 | Bottleneck Bandwidth Estimation Using Frequency AnalysisabstractThis paper presents a new passive technique for estimating the bottleneck bandwidth based on transferring the Gaussian kernel density estimation of the packets inter arrival times to the frequency domain. The resulting spectrum contains information about the transmission time of the bottleneck link and can reveal information about multiple bottlenecks if they exist along the end-to-end path. The advantage of the technique is that it provides a model that can be manipulated by the digital signal processing methods and, unlike prior work in the area, it relies less on statistical methods. The proposed technique was validated using the ns2 network simulator on several topologies and traffic sources. Further experiments were conducted to test the strength of the patterns between flows that share a bottleneck by applying K-means algorithm to cluster the average packet inter-arrival times of these flows. The paper also presents a set of results from real traffic experiments conducted in order to infer both the bottleneck bandwidth and the capacity of the path using a passive approach. Talal A. Edwan, Bogdan Ghita 0003, Xingang Wang 0002 |
ICCCN | 2 |